curl是瑞典curl团队开源的一款用于从服务器传输数据或向服务器传输数据的工具。 curl 8.21.0及之前版本存在会话机制问题漏洞,该漏洞源于libcurl重用HTTPS连接时未考虑Native CA Store设置,即使给定主机名使用与连接创建时不同的CURLSSLOPT_NATIVE_CA设置,也会错误地复用现有连接。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82208 | wolfSSL CA-cache hit overrides callback | |
| CVE-2026-82209 | domain-scoped PSL domain cookie | |
| CVE-2026-18924 | HTTP/2 server push UAF | |
| CVE-2026-19931 | Negotiate ambient user conn reuse | |
| CVE-2026-80229 | OpenSSL provider use-after-free | |
| CVE-2026-80230 | OpenSSL pinning bypass | |
| CVE-2026-80255 | secure cookie attribute bypass with tab | |
| CVE-2026-13608 | OpenLDAP SASL authentication bypass |
No comments yet